← back
CVE-2024-49112

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

CVSS 9.8 CRITICALEPSS 70.9%CWE-190
In short

A critical flaw in Windows LDAP allows attackers to execute malicious code remotely without authentication. This vulnerability affects a core Windows service used for directory and authentication services, putting systems at severe risk.

Technical detail

An integer overflow vulnerability (CWE-190) in Windows LDAP processing enables unauthenticated remote code execution through specially crafted LDAP requests. The vulnerability requires no credentials or user interaction, affecting the LDAP service directly accessible on the network.

Summary generated and translated by AI from the official description.
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →